VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,543)

page 6 of 2,328
  • CVE-2020-23718CriNov 2, 2021
    risk 0.63cvss 9.6epss 0.01

    Cross site scripting (XSS) vulnerability in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the route parameter to index.php.

  • CVE-2021-33501CriJul 19, 2021
    risk 0.63cvss 9.6epss 0.08

    Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.

  • CVE-2021-24229CriApr 12, 2021
    risk 0.63cvss 9.6epss 0.02

    The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to access a given…

  • CVE-2021-24228CriApr 12, 2021
    risk 0.63cvss 9.6epss 0.02

    The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users to authenticate on the site using their Patreon account.…

  • CVE-2021-29996CriApr 5, 2021
    risk 0.63cvss 9.6epss 0.03

    Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing a mutation Cross Site Scripting (XSS) payload.

  • CVE-2020-28149CriMar 15, 2021
    risk 0.63cvss 9.6epss 0.02

    myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The component is: CSRF Token. The attack vector is: CSRF token injection to XSS.

  • CVE-2021-3210CriFeb 19, 2021
    risk 0.63cvss 9.6epss 0.03

    components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.

  • CVE-2020-35125CriFeb 9, 2021
    risk 0.63cvss 9.6epss 0.03

    A cross-site scripting (XSS) vulnerability in the forms component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript via mautic[return] (a different attack method than CVE-2020-35124, but also related to the Referer concept).

  • CVE-2020-16608CriDec 10, 2020
    risk 0.63cvss 9.6epss 0.04

    Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).

  • CVE-2020-26574CriOct 6, 2020
    risk 0.63cvss 9.6epss 0.02

    Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the webquery.pl User-Agent HTTP header. It is rendered by the admins the next time they log in. The JavaScript injected can be used to force the…

  • CVE-2020-26158CriSep 30, 2020
    risk 0.63cvss 9.6epss 0.02

    Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.

  • CVE-2020-26157CriSep 30, 2020
    risk 0.63cvss 9.6epss 0.02

    Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.

  • CVE-2020-24594CriSep 25, 2020
    risk 0.63cvss 9.6epss 0.02

    Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.

  • CVE-2020-11749CriJul 13, 2020
    risk 0.63cvss 9.0epss 0.16

    Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.

  • CVE-2020-5901CriJul 1, 2020
    risk 0.63cvss 9.6epss 0.01

    In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.

  • CVE-2020-0872CriMar 12, 2020
    risk 0.63cvss 9.6epss 0.10

    A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'.

  • CVE-2020-9758CriMar 9, 2020
    risk 0.63cvss 9.6epss 0.02

    An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and passwords of the helpdesk employees in the URI. This leads to a privilege escalation, from…

  • CVE-2019-13364CriSep 13, 2019
    risk 0.63cvss 9.6epss 0.01

    admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.

  • CVE-2019-13363CriSep 13, 2019
    risk 0.63cvss 9.6epss 0.01

    admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit…

  • CVE-2018-18864CriNov 20, 2018
    risk 0.63cvss 9.6epss 0.02

    Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.